In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jun 22, 2022 |
| Freebsd | — | Upgrade jenkinsUpgrade jenkins-lts | Nov 4, 2022 | Jun 22, 2022 |
| Jenkins 2022 06 22 | — | Upgrade Jenkins to version 2.356Upgrade Jenkins LTS to version 2.332.4Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest version | Jul 12, 2022 | Jun 22, 2022 |
| Redhat Openshift | — | Upgrade jenkins | Jan 13, 2023 | Jun 22, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub